Skip to content

Commit

Permalink
Docs: Improve zerologon explanation
Browse files Browse the repository at this point in the history
  • Loading branch information
mssalvatore committed Jul 23, 2024
1 parent 73a67f2 commit 7b0c18f
Showing 1 changed file with 7 additions and 7 deletions.
14 changes: 7 additions & 7 deletions docs/content/features/exploiters/zerologon.md
Original file line number Diff line number Diff line change
Expand Up @@ -28,8 +28,8 @@ and account management, is severely affected.

Due to a flaw in the cryptographic authentication scheme of Netlogon, an
attacker can bypass authentication and gain administrator-level privileges to
a machine, including a domain controller, effectively granting the attacker
control over the entire domain.
an unpatched machine, including a domain controller, effectively granting the
attacker control over the entire domain.

Infection Monkey's Zerologon exploiter takes advantage of this vulnerability to
steal credentials from the domain controller, which are then used to propagate
Expand All @@ -47,13 +47,12 @@ https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-1472).

## A note on safety

This exploiter is not safe for production or other sensitive environments. It
is, therefore, **not** enabled by default.

This exploiter is not safe for production or other sensitive environments.
During successful exploitation, the Zerologon exploiter:

* Will temporarily change the target domain controller's password.
* May break the target domain controller's communication with other systems in the network, affecting functionality.
* May break the target domain controller's communication with other systems in
the network, affecting functionality.
* May change the administrator's password.
* Will *attempt* to revert all changes.

Expand Down Expand Up @@ -97,4 +96,5 @@ If all other approaches fail, you can try the tools and steps found
[here](https://github.com/risksense/zerologon).

## See also
- [Zerologon exploiter reference documentation](/reference/exploiters/zerologon)
- [Zerologon exploiter reference
documentation](/reference/exploiters/zerologon)

0 comments on commit 7b0c18f

Please sign in to comment.